Skip site navigation (1)Skip section navigation (2)
Date:      Sun, 25 Feb 2024 18:28:27 +0100
From:      Moin Rahman <bofh@freebsd.org>
To:        Michael Grimm <trashcan@ellael.org>
Cc:        FreeBSD Mailing List <freebsd-ports@freebsd.org>, freebsd@dns.company
Subject:   Re: dns/knot-resolver security update to 5.7.1 (was: dns/knot3 update to 3.3.4)
Message-ID:  <A733B3C9-F916-403A-9312-FD3F359D0B6B@freebsd.org>
In-Reply-To: <689E4249-F841-4B39-94E0-F2725518BFA0@ellael.org>
References:  <14DA84EE-3CC0-454E-967A-CBFF40C06ABD@ellael.org> <232E3D69-782B-49A7-9B82-AA59765DA98B@freebsd.org> <689E4249-F841-4B39-94E0-F2725518BFA0@ellael.org>

next in thread | previous in thread | raw e-mail | index | archive | help

--Apple-Mail=_19274ECA-2DCC-4B38-BC8E-34C206DAF21A
Content-Transfer-Encoding: quoted-printable
Content-Type: text/plain;
	charset=utf-8



> On Feb 25, 2024, at 6:15 PM, Michael Grimm <trashcan@ellael.org> =
wrote:
>=20
> Moin Rahman <bofh@FreeBSD.org> wrote:
>=20
>>> On Feb 25, 2024, at 5:04 PM, Michael Grimm <trashcan@ellael.org> =
wrote:
>>>=20
>>> a new version of this port has been released two month ago.
>>>=20
>>> The maintainer normally updates knot3 shortly after the release of a =
new version. He didn't react on a mail of mine. No pun intended, there =
are numerous reasons for that.
>>>=20
>>> I do have a git-diff patch at hand, successfully compiling with =
poudriere, and running well for 1 month now.
>>>=20
>>> What can I do to get this patch committed?
>>> Shall I create a PR like =
https://cgit.freebsd.org/ports/commit/?id=3D11f44f375254e07a262455aaf8311b=
fd4bbedb67
>=20
>> It's best to create a PR and awaiting for maintainer-timeout.
>=20
> Done, https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=3D277305
I will let time take it's course of action.

>> However on certain cases like security or vulnerability issues the =
update
>> can be committed without the maintainer-approval. So if this is a =
release
>> related to the recent dnssec security issue let me know.
>=20
> dns/knot3 as an authoritative DNS server isn't affected by =
CVE-2023-50868, if I am not mistaken. Ain't no DNS expert =E2=80=A6
>=20
> BUT, dns/knot-resolver is affected: =
https://gitlab.nic.cz/knot/knot-resolver/-/releases/v5.7.1
>=20
> I do not use that port, yet.
> But I opened another PR on that security update to dns/knot-resolver: =
https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=3D277306
>=20
> All I can say is: dns/knot-resolver 5.7.1 compiles with poudriere.
I will commit this soonish.

> HTH,
> Michael
>=20
> P.S. Please forgive my lack in experience with PRs ;-)
>     Please let me know, what to correct if neccessary

Well as a starter:
1. You do not need PORTREVISION when you already bumping PORTVERSION or =
updating versions. I will fix it while committing.
2. Follow this process:
   a. Initially create the PR with synopsis and description.
   b. Create git-formatted patch
   c. Read this section of the documentation:
      =
https://docs.freebsd.org/en/articles/committers-guide/#git-mini-daily-use
   d. Specially the git hook part and try to use the hook from here:
      https://cgit.freebsd.org/ports/tree/.hooks/prepare-commit-msg
   e. Now make a commit to your local branch with the description, PR =
etc whatever is relevant.
   f. Create a git formatted patch and attach it to the PR.

While people think this is difficult workflow it actually makes our life =
easier as we also have to do the same and also helps us attributing =
external developers more easily.

Kind regards,
Moin


--Apple-Mail=_19274ECA-2DCC-4B38-BC8E-34C206DAF21A
Content-Transfer-Encoding: 7bit
Content-Disposition: attachment;
	filename=signature.asc
Content-Type: application/pgp-signature;
	name=signature.asc
Content-Description: Message signed with OpenPGP

-----BEGIN PGP SIGNATURE-----

iQKTBAEBCgB9FiEETfdREoUGjQZKBS+fvbm1phfAvJEFAmXbeLtfFIAAAAAALgAo
aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldDRE
Rjc1MTEyODUwNjhEMDY0QTA1MkY5RkJEQjlCNUE2MTdDMEJDOTEACgkQvbm1phfA
vJEIUg//ZIMUPdARv+QR9bR8YwvBFwo9DOLn1fwZ4B9tBJkKEYGnUbb51Tqh+5hE
UidBY0Gc0wru8Zz/6cLKjWU9sB+wQcpwsAJOPoeQRlVwJfSNTEqXRUwHwaAa5L7h
KWTC5ltbikx5jZJ332y+WdftOewTyAiR7zRCgxF/CbFW0w83ryKVgRIQ+4RAS/ri
qM1HKaRs617cso3ZGSxntWGFejSbPP3hCKVOPFBl6mBB+pGrsJjt22CBynmPSvVf
PZloJM9QStTtvDLOjy1eJLdxEO9dD1RzKrusYr6SgzfTjrmbOU/U0/H1MOQDX6ye
vGYkCwWES6Uzup14RwIMXVCKcoFjcm6Y8HHChvq1N7hZHgmA5C30hI75JttYhl9T
oj+0ta6hI8KMrhc/4gRy7Shm6EAMQ+lrf95yZnr2LLquebykVd0LnxsJ2anK+/5/
6zSwIX735g4fYNyYhCFit3Tk3/jPQnHDsnpmkU+X/Zr5B2mj9i00fsbbWmLPhBzA
zO6Xho0LSZzv4TXGhO7Y49KN2VWIFIWQhoIPzUpExfNrhOjADsc4fRtuYEYf6vMs
y910E7aBZ/LG0VOdTrXjZOXnHDftewFsV5uTZm+HvD2IdeDBCccU+bTrRhJdf8Wg
EMykIgC0u0rqV/jNmesADWMTDZLQGkgyeY242TIYHh0X5ver7fw=
=4hJj
-----END PGP SIGNATURE-----

--Apple-Mail=_19274ECA-2DCC-4B38-BC8E-34C206DAF21A--



Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?A733B3C9-F916-403A-9312-FD3F359D0B6B>